{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/gtm4wp/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-16597"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GTM4WP (Google Tag Manager for WordPress plugin) (\u003c= 1.22.3)","WooCommerce"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","xss","web-vulnerability","e-commerce"],"_cs_type":"advisory","_cs_vendors":["GTM4WP","Automattic"],"content_html":"\u003cp\u003eThe GTM4WP - A Google Tag Manager (GTM) plugin for WordPress, in all versions up to and including 1.22.3, contains a critical stored cross-site scripting (XSS) vulnerability tracked as CVE-2026-16597. This flaw arises from insufficient input sanitization and output escaping when processing WooCommerce billing fields. Unauthenticated attackers can exploit this by submitting a guest checkout order through WooCommerce with a JavaScript payload embedded in billing fields, such as the first name. Successful exploitation requires the \u003ccode\u003eGTM4WP_OPTION_INTEGRATE_WCORDERDATA\u003c/code\u003e option to be enabled within the plugin's settings. Once injected, the malicious script executes whenever a user, including administrators, accesses a page displaying the compromised order data, potentially leading to session hijacking, credential theft, or further website defacement.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site running the vulnerable GTM4WP plugin (version 1.22.3 or earlier) with WooCommerce enabled.\u003c/li\u003e\n\u003cli\u003eThe attacker browses the WordPress site as a guest user and adds an item to their shopping cart.\u003c/li\u003e\n\u003cli\u003eThe attacker proceeds to the WooCommerce guest checkout page.\u003c/li\u003e\n\u003cli\u003eDuring the checkout process, the attacker injects a malicious JavaScript payload (e.g., \u003ccode\u003e\u0026lt;script\u0026gt;alert(document.cookie)\u0026lt;/script\u0026gt;\u003c/code\u003e) into a WooCommerce billing field, such as \u0026quot;Billing first name,\u0026quot; and completes the guest order.\u003c/li\u003e\n\u003cli\u003eThe GTM4WP plugin, with the \u003ccode\u003eGTM4WP_OPTION_INTEGRATE_WCORDERDATA\u003c/code\u003e option enabled, stores this unsanitized JavaScript payload as part of the order data in the WordPress database.\u003c/li\u003e\n\u003cli\u003eA legitimate, often privileged, user (e.g., a site administrator, store manager) accesses the order details page within the WordPress administrative dashboard to review the newly placed order.\u003c/li\u003e\n\u003cli\u003eWhen the browser renders the order details page, the stored malicious JavaScript payload executes in the legitimate user's browser context.\u003c/li\u003e\n\u003cli\u003eThe attacker's script could then perform actions such as session hijacking, defacement of the admin interface, redirection to malicious sites, or exfiltration of sensitive information, achieving unauthorized control or data access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16597 allows unauthenticated attackers to execute arbitrary web scripts in the context of a victim user's browser. This can lead to various severe consequences, including session hijacking of administrative users, complete website defacement, redirection of legitimate users to phishing or malicious sites, or unauthorized data theft from the compromised user's session. The widespread use of WordPress and WooCommerce means a significant number of e-commerce sites could be vulnerable, potentially impacting customer data privacy and business operations if an attacker gains control over a privileged user's session.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-16597 by updating the GTM4WP - A Google Tag Manager (GTM) plugin for WordPress plugin to version 1.22.4 or higher immediately.\u003c/li\u003e\n\u003cli\u003eEnsure that log sources for web servers (e.g., Apache, Nginx) are configured to capture full HTTP POST requests, specifically for paths related to WooCommerce checkout, to enable detection of JavaScript injection attempts as described in the \u003ccode\u003eDetect CVE-2026-16597 XSS Injection Attempt on WooCommerce Checkout\u003c/code\u003e rule.\u003c/li\u003e\n\u003cli\u003eReview web application firewall (WAF) configurations to ensure they actively filter for common cross-site scripting (XSS) patterns, particularly on input fields for WooCommerce.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u003ccode\u003eDetect CVE-2026-16597 XSS Injection Attempt on WooCommerce Checkout\u003c/code\u003e to your SIEM and tune for your environment to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T11:20:33Z","date_published":"2026-07-29T11:20:33Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16597-gtm4wp-xss/","summary":"The GTM4WP (Google Tag Manager) plugin for WordPress, in versions up to and including 1.22.3, is vulnerable to stored cross-site scripting (XSS) via CVE-2026-16597, allowing unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields during a guest checkout, which execute when a user accesses the compromised page.","title":"CVE-2026-16597 - GTM4WP WordPress Plugin Vulnerable to Stored XSS via WooCommerce Billing Fields","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16597-gtm4wp-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - GTM4WP","version":"https://jsonfeed.org/version/1.1"}